Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0667-1

Опубликовано: 16 мар. 2015
Источник: suse-cvrf

Описание

Security update for libarchive

libarchive was updated to fix a directory traversal in the bsdcpio tool, which allowed attackers supplying crafted archives to overwrite files. (CVE-2015-2304)

Also, a integer overflow was fixed that could also overflow buffers. (CVE-2013-0211)

Список пакетов

SUSE Linux Enterprise Desktop 12
libarchive13-3.1.2-9.1
SUSE Linux Enterprise Server 12
libarchive13-3.1.2-9.1
SUSE Linux Enterprise Server for SAP Applications 12
libarchive13-3.1.2-9.1
SUSE Linux Enterprise Software Development Kit 12
libarchive-devel-3.1.2-9.1

Описание

Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:libarchive13-3.1.2-9.1
SUSE Linux Enterprise Server 12:libarchive13-3.1.2-9.1
SUSE Linux Enterprise Server for SAP Applications 12:libarchive13-3.1.2-9.1
SUSE Linux Enterprise Software Development Kit 12:libarchive-devel-3.1.2-9.1

Ссылки

Описание

Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:libarchive13-3.1.2-9.1
SUSE Linux Enterprise Server 12:libarchive13-3.1.2-9.1
SUSE Linux Enterprise Server for SAP Applications 12:libarchive13-3.1.2-9.1
SUSE Linux Enterprise Software Development Kit 12:libarchive-devel-3.1.2-9.1

Ссылки